← WordPress Vulnerabilities
WordPress security by component

Total Upkeep

Total Upkeep is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 8.2.

Plugin slug: boldgrid-backup

CVE-2026-66708: Total Upkeep permits unauthenticated access to protected functionality

An unauthenticated visitor can reach a Total Upkeep operation that lacks the required authorization check in version 1.17.2 and earlier. The CNA does not disclose the endpoint or action, parameter, missing check, protected operation or exact impact.

PublishedAug 06, 2026
Known safe version1.17.3
Published vulnerabilities for boldgrid-backup
Safe version
Aug 06, 2026 CVE-2026-66708
Total Upkeep permits unauthenticated access to protected functionality
An unauthenticated visitor can reach a Total Upkeep operation that lacks the required authorization check in version 1.17.2 and earlier. The CNA does not disclose the endpoint or action, parameter, missing check, protected operation or exact impact.
1.17.3
CVE8.2
NVDPending
May 01, 2026 CVE-2026-3143
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid: A security weakness
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.17.1.
> 1.17.1
CVE5.3
NVDPending
Feb 27, 2025 CVE-2024-13907
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid: Server-side request forgery
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.9
NVD6.5
Nov 26, 2024 CVE-2024-9461
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid: Code execution
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
May 17, 2024 CVE-2024-24869
Total Upkeep: Filesystem traversal
Total Upkeep is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending